Skip to content

NO-ISSUE: Synchronize From Upstream Repositories - #788

Merged
openshift-merge-bot[bot] merged 139 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream
Aug 12, 2026
Merged

NO-ISSUE: Synchronize From Upstream Repositories#788
openshift-merge-bot[bot] merged 139 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream

Conversation

@openshift-bot

@openshift-botopenshift-bot commented Aug 4, 2026

Copy link
Copy Markdown

The downstream repository has been updated with the following following upstream commits:

DateCommitAuthorMessage
2026-08-11 03:39:03operator-framework/operator-controller@d9427eadependabot[bot]🌱 bump pyquery from 2.0.1 to 2.1.0 (#2869)
2026-08-11 03:35:57operator-framework/operator-controller@9046f7edependabot[bot]🌱 bump github.com/spf13/cobra in /hack/tools/test-profiling (#2868)
2026-08-10 20:39:58operator-framework/operator-controller@68a24d6dependabot[bot]🌱 bump k8s.io/client-go in /hack/tools/test-profiling (#2866)
2026-08-10 20:10:37operator-framework/operator-controller@798436edependabot[bot]🌱 bump k8s.io/apimachinery in /hack/tools/test-profiling (#2867)
2026-08-10 19:50:42operator-framework/operator-controller@df55266dependabot[bot]🌱 bump docker/login-action from 4.5.0 to 4.5.2 (#2865)
2026-08-10 19:47:16operator-framework/operator-controller@6936a19dependabot[bot]🌱 bump cssselect from 1.4.0 to 1.5.0 (#2864)
2026-08-10 19:43:51operator-framework/operator-controller@07d2785dependabot[bot]🌱 bump actions/stale from 10.4.0 to 11.0.0 (#2862)
2026-08-10 19:40:42operator-framework/operator-controller@e070eb7dependabot[bot]🌱 bump github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2 (#2860)
2026-08-10 19:37:33operator-framework/operator-controller@7a0c49adependabot[bot]🌱 bump github.com/prometheus/client_golang (#2859)
2026-08-10 19:34:04operator-framework/operator-controller@b7e7810Todd Shortci: add dependabot config for nested Go modules (#2857)
2026-08-10 19:30:57operator-framework/operator-controller@aff7b5bTodd Short🌱 Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#2856)
2026-08-07 04:13:11operator-framework/operator-controller@1e9e659Predrag Knezevicupdate repo owners (#2852)
2026-08-06 20:03:47operator-framework/operator-controller@be1115edependabot[bot]🌱 Bump docker/login-action from 4.4.0 to 4.5.0 (#2855)
2026-08-06 19:59:49operator-framework/operator-controller@d854c6edependabot[bot]🌱 Bump github.com/santhosh-tekuri/jsonschema/v6 (#2854)
2026-08-06 19:55:56operator-framework/operator-controller@fb11d94dependabot[bot]🌱 Bump the k8s-dependencies group with 4 updates (#2853)
2026-08-05 18:22:34operator-framework/operator-controller@6603a82dependabot[bot]🌱 Bump soupsieve from 2.9 to 2.9.1 (#2851)
2026-08-05 18:18:25operator-framework/operator-controller@23256c7dependabot[bot]🌱 Bump certifi from 2026.6.17 to 2026.7.22 (#2850)
2026-08-05 18:14:48operator-framework/operator-controller@488a402dependabot[bot]🌱 Bump github.com/prometheus/common from 0.70.0 to 0.70.1 (#2849)
2026-08-05 17:43:51operator-framework/operator-controller@fee8cc2Predrag Knezevicfix: collect operator pod logs across restarts and rolling updates (#2848)
2026-08-04 20:44:51operator-framework/operator-controller@9c2ba82dependabot[bot]🌱 Bump platformdirs from 4.10.1 to 4.11.0 (#2846)
2026-08-03 18:07:27operator-framework/operator-controller@255f5dePredrag Knezevicfix: make demo e2e catalog queries resilient to transient failures (#2838)
2026-08-03 18:03:57operator-framework/operator-controller@0a6b0bedependabot[bot]🌱 Bump soupsieve from 2.8.4 to 2.9 (#2843)
2026-08-03 15:37:12operator-framework/operator-controller@fdaba96dependabot[bot]🌱 Bump github.com/klauspost/compress from 1.19.0 to 1.19.1 (#2845)
2026-08-03 15:34:31operator-framework/operator-controller@6145027dependabot[bot]🌱 Bump github.com/prometheus/client_golang (#2844)
2026-08-03 15:23:15operator-framework/operator-controller@d298851dependabot[bot]🌱 Bump regex from 2026.7.10 to 2026.7.19 (#2842)
2026-08-03 15:20:31operator-framework/operator-controller@689f632dependabot[bot]🌱 Bump platformdirs from 4.10.0 to 4.10.1 (#2841)
2026-08-03 15:17:13operator-framework/operator-controller@3240aa5dependabot[bot]🌱 Bump mkdocs-material from 9.7.6 to 9.7.7 (#2840)
2026-08-03 15:14:17operator-framework/operator-controller@0273129dependabot[bot]🌱 Bump actions/setup-python from 6.3.0 to 7.0.0 (#2839)
2026-07-31 16:38:07operator-framework/operator-controller@7db5d14dependabot[bot]🌱 Bump actions/checkout from 7.0.0 to 7.0.1 (#2837)
2026-07-29 15:39:34operator-framework/operator-controller@7ec6a0edependabot[bot]🌱 Bump actions/setup-go from 6.5.0 to 7.0.0 (#2836)

The vendor/ directory has been updated and the following commits were carried:

DateCommitAuthorMessage
2026-07-29 00:08:34openshift/operator-framework-operator-controller@2e7026cdtfranzUPSTREAM: <carry>: Add OpenShift specific files
2026-07-29 00:08:36openshift/operator-framework-operator-controller@2bb3a8aCamila MacedoUPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-07-29 00:08:37openshift/operator-framework-operator-controller@d1f3208Camila MacedoUPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-07-29 00:08:37openshift/operator-framework-operator-controller@b2fc6f3Camila MacedoUPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-07-29 00:08:38openshift/operator-framework-operator-controller@51b04ddTodd ShortUPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-07-29 00:08:39openshift/operator-framework-operator-controller@5fa95cdKui WangUPSTREAM: <carry>: support singleown cases in disconnected
2026-07-29 00:08:40openshift/operator-framework-operator-controller@135baedKui WangUPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-07-29 00:08:40openshift/operator-framework-operator-controller@ea99d97Camila MacedoUPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-07-29 00:08:41openshift/operator-framework-operator-controller@99bc51dTodd ShortUPSTREAM: <carry>: Update to new feature-gate options in helm
2026-07-29 00:08:42openshift/operator-framework-operator-controller@fe0de94Camila MacedoUPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-07-29 00:08:43openshift/operator-framework-operator-controller@4a92d7aCamila MacedoUPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-07-29 00:08:43openshift/operator-framework-operator-controller@8d66b27Kui WangUPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-07-29 00:08:44openshift/operator-framework-operator-controller@832f4a1Camila MacedoUPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-07-29 00:08:45openshift/operator-framework-operator-controller@639ef87Kui WangUPSTREAM: <carry>: Add [OTP] to migrated cases
2026-07-29 00:08:46openshift/operator-framework-operator-controller@5d89946Camila MacedoUPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-07-29 00:08:47openshift/operator-framework-operator-controller@aaa0df1Camila MacedoUPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-07-29 00:08:48openshift/operator-framework-operator-controller@8026046Camila MacedoUPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-07-29 00:08:49openshift/operator-framework-operator-controller@0a62a52Kui WangUPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-07-29 00:08:50openshift/operator-framework-operator-controller@8ce3742Jian ZhangUPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-07-29 00:08:51openshift/operator-framework-operator-controller@e965588Xia ZhaoUPSTREAM: <carry>: migrate clustercatalog case to ote
2026-07-29 00:08:51openshift/operator-framework-operator-controller@bde51deKui WangUPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-07-29 00:08:52openshift/operator-framework-operator-controller@b2fa498Todd ShortUPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-07-29 00:08:53openshift/operator-framework-operator-controller@b6100d0Xia ZhaoUPSTREAM: <carry>: migrate olmv1 QE cases
2026-07-29 00:08:53openshift/operator-framework-operator-controller@489171aKui WangUPSTREAM: <carry>: add agent for olmv1 qe cases
2026-07-29 00:08:54openshift/operator-framework-operator-controller@1f808b6Todd ShortUPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-07-29 00:08:55openshift/operator-framework-operator-controller@2014dfaRashmi GottipatiUPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-07-29 00:08:55openshift/operator-framework-operator-controller@33a90ebRashmi GottipatiUPSTREAM: <carry>: address review comments through addl prompts
2026-07-29 00:08:56openshift/operator-framework-operator-controller@ea7e63fRashmi GottipatiUPSTREAM: <carry>: addressing some more review comments
2026-07-29 00:08:57openshift/operator-framework-operator-controller@162219aRashmi GottipatiUPSTREAM: <carry>: remove DCO line
2026-07-29 00:08:57openshift/operator-framework-operator-controller@3f9cd8eBruno AndradeUPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-07-29 00:08:58openshift/operator-framework-operator-controller@78db4c7Bruno AndradeUPSTREAM: <carry>: update metadata
2026-07-29 00:08:59openshift/operator-framework-operator-controller@19cc3fcBruno AndradeUPSTREAM: <carry>: remove originalName
2026-07-29 00:08:59openshift/operator-framework-operator-controller@e89f1c2Jian ZhangUPSTREAM: <carry>: update 80458's timeout to 180s
2026-07-29 00:09:00openshift/operator-framework-operator-controller@4247a95Jian ZhangUPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-07-29 00:09:01openshift/operator-framework-operator-controller@4c8f275Catherine Chan-TseUPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-07-29 00:09:01openshift/operator-framework-operator-controller@e1bb13cPredrag KnezevicUPSTREAM: <carry>: Use oc client for running e2e tests
2026-07-29 00:09:02openshift/operator-framework-operator-controller@18c8babPredrag KnezevicUPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-07-29 00:09:03openshift/operator-framework-operator-controller@4ad733fKui WangUPSTREAM: <carry>: enhance case to make it more stable
2026-07-29 00:09:03openshift/operator-framework-operator-controller@bd4dd40Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-07-29 00:09:04openshift/operator-framework-operator-controller@857a3ebEvan HearneUPSTREAM: <carry>: move sa creation out of buildCurlJob()
2026-07-29 00:09:05openshift/operator-framework-operator-controller@a68dc2aEvan HearneUPSTREAM: <carry>: comment out delete service account
2026-07-29 00:09:06openshift/operator-framework-operator-controller@d899f37Evan HearneUPSTREAM: <carry>: move defercleanup for sa for LIFO
2026-07-29 00:09:06openshift/operator-framework-operator-controller@c54245cEvan HearneUPSTREAM: <carry>: add polling so job fully deleted before proceed
2026-07-29 00:09:07openshift/operator-framework-operator-controller@0a3a6a8Luke MeyerUPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redhat/add-service-account-curl-job"
2026-07-29 00:09:08openshift/operator-framework-operator-controller@6d4351fCamila MacedoUPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
2026-07-29 00:09:08openshift/operator-framework-operator-controller@477ed9cKui WangUPSTREAM: <carry>: config watchnamespace cases
2026-07-29 00:09:09openshift/operator-framework-operator-controller@ee080ddXia ZhaoUPSTREAM: <carry>: enhance ocp-79770
2026-07-29 00:09:10openshift/operator-framework-operator-controller@97ca4a9Kui WangUPSTREAM: <carry>: upgrade version support case
2026-07-29 00:09:10openshift/operator-framework-operator-controller@b37dffaPer Goncalves da SilvaUPSTREAM: <carry>: Remove installed condition check from auth preflight test
2026-07-29 00:09:11openshift/operator-framework-operator-controller@7003366Per Goncalves da SilvaUPSTREAM: <carry>: Add openshift/api dependency
2026-07-29 00:09:12openshift/operator-framework-operator-controller@147e323Per Goncalves da SilvaUPSTREAM: <carry>: Add boxcutter specific preflight auth test
2026-07-29 00:09:12openshift/operator-framework-operator-controller@cdec935Kui WangUPSTREAM: <carry>: adjust watchnamespace case based on change
2026-07-29 00:09:13openshift/operator-framework-operator-controller@03a3386Camila MacedoUPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root dir
2026-07-29 00:09:14openshift/operator-framework-operator-controller@adc763aBruno AndradeUPSTREAM: <carry>: add 83979 automation
2026-07-29 00:09:14openshift/operator-framework-operator-controller@183bc8dBruno AndradeUPSTREAM: <carry>: add 85889 automation
2026-07-29 00:09:15openshift/operator-framework-operator-controller@0d38d0dPer Goncalves da SilvaUPSTREAM: <carry>: Update test-operator startup script to fix pod probe endpoints
2026-07-29 00:09:16openshift/operator-framework-operator-controller@b5d0f94Per Goncalves da SilvaUPSTREAM: <carry>: Fix up own-namespace invalid configuration test
2026-07-29 00:09:16openshift/operator-framework-operator-controller@158ec9cCamila MacedoUPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles instead of openshift-pipelines-operator-rh
2026-07-29 00:09:17openshift/operator-framework-operator-controller@f8602b6Kui WangUPSTREAM: <carry>: adjust sa and permission test cases per new change from boxcutterruntime
2026-07-29 00:09:18openshift/operator-framework-operator-controller@c5c79acCamila MacedoUPSTREAM: <carry>: Update OCP catalogs to v4.22
2026-07-29 00:09:19openshift/operator-framework-operator-controller@7828832Camila MacedoUPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and dependencies
2026-07-29 00:09:20openshift/operator-framework-operator-controller@276fbbcJian ZhangUPSTREAM: <carry>: fix 83026 for TP cluster
2026-07-29 00:09:21openshift/operator-framework-operator-controller@b6bda60Kui WangUPSTREAM: <carry>: serviceAccount validation unified across all runtimes
2026-07-29 00:09:22openshift/operator-framework-operator-controller@3ec750eStephen BenjaminUPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
2026-07-29 00:09:22openshift/operator-framework-operator-controller@03fa5c0Camila MacedoUPSTREAM: <carry>: Increase install timeout and add diagnostic logging for CE install tests
2026-07-29 00:09:23openshift/operator-framework-operator-controller@ec0fc4fEvan HearneUPSTREAM: <carry>: add service account to curl job
2026-07-29 00:09:23openshift/operator-framework-operator-controller@48a0c82Jian ZhangUPSTREAM: <carry>: update OCP-75441 to support multi-arch
2026-07-29 00:09:24openshift/operator-framework-operator-controller@5126b61Kui WangUPSTREAM: <carry>: deployment config cases
2026-07-29 00:09:25openshift/operator-framework-operator-controller@dbd3c66Todd ShortUPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
2026-07-29 00:09:26openshift/operator-framework-operator-controller@0d57d47Todd ShortUPSTREAM: <carry>: Update openshift/api and client-go
2026-07-29 00:09:26openshift/operator-framework-operator-controller@6d5ebf2Camila MacedoUPSTREAM: <carry>: Add boxcutter tests
2026-07-29 00:09:27openshift/operator-framework-operator-controller@08d0f6fXia ZhaoUPSTREAM: <carry>: enhance QE cases
2026-07-29 00:09:28openshift/operator-framework-operator-controller@aa7522eDaniel FranzUPSTREAM: <carry>: Update quay-operator version to one containing arm64 support
2026-07-29 00:09:28openshift/operator-framework-operator-controller@498338bKui WangUPSTREAM: <carry>: verify volume/volumeMount override
2026-07-29 00:09:29openshift/operator-framework-operator-controller@382cdb8Jian ZhangUPSTREAM: <carry>: Add long-duration test script and documents
2026-07-29 00:09:30openshift/operator-framework-operator-controller@8191908Todd ShortUPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
2026-07-29 00:09:31openshift/operator-framework-operator-controller@34c2a3dCamila MacedoUPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSet in OTE tests
2026-07-29 00:09:32openshift/operator-framework-operator-controller@90bc5efCamila MacedoUPSTREAM: <carry>: Skip incompatible operator test when Boxcutter uses ClusterObjectSet
2026-07-29 00:09:32openshift/operator-framework-operator-controller@733b829Bruno AndradeUPSTREAM: <carry>: add ocp-87557
2026-07-29 00:09:33openshift/operator-framework-operator-controller@87a2a7fFrancesco GiudiciUPSTREAM: <carry>: Add fgiudici as reviewer
2026-07-29 00:09:34openshift/operator-framework-operator-controller@93fd425Camila MacedoUPSTREAM: <carry>: Remove skip for incompatible operator check after rename of CER
2026-07-29 00:09:34openshift/operator-framework-operator-controller@b3d9234Kui WangUPSTREAM: <carry>: Test empty affinity erasure and cleanup
2026-07-29 00:09:35openshift/operator-framework-operator-controller@093e927Camila MacedoUPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in preflight test
2026-07-29 00:09:36openshift/operator-framework-operator-controller@28f4992Camila MacedoUPSTREAM: <carry>: Expand OTE docs with more comprehensive details
2026-07-29 00:09:36openshift/operator-framework-operator-controller@cc35128Todd ShortUPSTREAM: <carry>: Disable upstream TLSProfile tests
2026-07-29 00:09:37openshift/operator-framework-operator-controller@759899bCamila MacedoUPSTREAM: <carry>: OTE: Simplify by remove option to configure tests to run outside of OCP
2026-07-29 00:09:38openshift/operator-framework-operator-controller@2fb21b1Camila MacedoUPSTREAM: <carry>: OTE - Make OTE local output easier to read
2026-07-29 00:09:39openshift/operator-framework-operator-controller@8267e25Joe LanfordUPSTREAM: <carry>: remove dead e2e registry push job and related variables
2026-07-29 00:09:40openshift/operator-framework-operator-controller@7ed9698Todd ShortUPSTREAM: <carry>: OCPBUGS-62517: Set replicas=1, PDB, and pod anti-affinity for HA topology
2026-07-29 00:09:41openshift/operator-framework-operator-controller@c238f0fTodd ShortUPSTREAM: <carry>: fix(test): drop blocking namespace-deletion wait between both-watch-modes scenarios
2026-07-29 00:09:42openshift/operator-framework-operator-controller@5739a9eTodd ShortUPSTREAM: <carry>: Fix downstream e2e test invocation
2026-07-29 00:09:43openshift/operator-framework-operator-controller@0831969Joe LanfordUPSTREAM: <carry>: Delete openshift/registry.Dockerfile
2026-07-29 00:09:44openshift/operator-framework-operator-controller@9b50613Todd ShortUPSTREAM: <carry>: Remove test-experimenal-e2e
2026-07-29 00:09:45openshift/operator-framework-operator-controller@3785c88Camila MacedoUPSTREAM: <carry>: Update readme Default Catalog Tests
2026-07-29 00:09:46openshift/operator-framework-operator-controller@ecaf2c6Todd ShortUPSTREAM: <carry>: add OLMv1 topology-based deployment scaling e2e test
2026-07-29 00:09:48openshift/operator-framework-operator-controller@a002887Todd ShortUPSTREAM: <carry>: Update dockerfiles to use golang-1.26-release-4.23 builders
2026-07-29 00:09:49openshift/operator-framework-operator-controller@4b5d24dAOS Automation Release TeamUPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-operator-controller.yml
2026-07-29 00:09:50openshift/operator-framework-operator-controller@90a3ae9AOS Automation Release TeamUPSTREAM: <carry>: Updating ose-olm-catalogd-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-catalogd.yml
2026-07-29 00:09:51openshift/operator-framework-operator-controller@559ef81Todd ShortUPSTREAM: <carry>: Update catalogs for 4.23/5.0
2026-07-29 00:09:53openshift/operator-framework-operator-controller@ef82bbaPer G. da SilvaUPSTREAM: <carry>: Remove HelmChartSupport feature gate from experimental manifests
2026-07-29 00:09:54openshift/operator-framework-operator-controller@4fd2ca9Todd ShortUPSTREAM: <carry>: test: add allow-case for operator maxOCPVersion > cluster version
2026-07-29 00:09:55openshift/operator-framework-operator-controller@a192469Daniel FranzUPSTREAM: <carry>: Add OLMv1 progress deadline QE tests
2026-07-29 00:09:56openshift/operator-framework-operator-controller@e006f96Todd ShortUPSTREAM: <carry>: Remove stale reviewers/approvers, add trgeiger
2026-07-29 00:09:57openshift/operator-framework-operator-controller@6856d00Daniel FranzUPSTREAM: <carry>: Remove openshift/ e2e related to deprecated ServiceAccount usage in ClusterExtension API, Synthetic Permissions, and PreFlight Admissions
2026-07-29 00:09:58openshift/operator-framework-operator-controller@9f51d6eTodd ShortUPSTREAM: <carry>: fix(test): update PolarionID:87224 for 4.23/5.0 upgrade boundary

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

dependabotBotand others added 10 commits July 29, 2026 15:39
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.5.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v6.5.0...v7.0.0)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v7.0.0...v7.0.1)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.3.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v6.3.0...v7.0.0)
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [mkdocs-material](https://github.com/squidfunk/mkdocs-material) from 9.7.6 to 9.7.7.
- [Release notes](https://github.com/squidfunk/mkdocs-material/releases)
- [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG)
- [Commits](squidfunk/mkdocs-material@9.7.6...9.7.7)
---
updated-dependencies:
- dependency-name: mkdocs-material
dependency-version: 9.7.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [platformdirs](https://github.com/tox-dev/platformdirs) from 4.10.0 to 4.10.1.
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.10.0...4.10.1)
---
updated-dependencies:
- dependency-name: platformdirs
dependency-version: 4.10.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [regex](https://github.com/mrabarnett/mrab-regex) from 2026.7.10 to 2026.7.19.
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](mrabarnett/mrab-regex@2026.7.10...2026.7.19)
---
updated-dependencies:
- dependency-name: regex
dependency-version: 2026.7.19
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) from 1.23.2 to 1.24.0.
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/v1.24.0/CHANGELOG.md)
- [Commits](prometheus/client_golang@v1.23.2...v1.24.0)
---
updated-dependencies:
- dependency-name: github.com/prometheus/client_golang
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/klauspost/compress](https://github.com/klauspost/compress) from 1.19.0 to 1.19.1.
- [Release notes](https://github.com/klauspost/compress/releases)
- [Commits](klauspost/compress@v1.19.0...v1.19.1)
---
updated-dependencies:
- dependency-name: github.com/klauspost/compress
dependency-version: 1.19.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.8.4 to 2.9.
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.8.4...2.9)
---
updated-dependencies:
- dependency-name: soupsieve
dependency-version: '2.9'
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2838)
The generate-demos CI job fails ~45% of the time with jq exit status 5
on the ClusterCatalog Quickstart scenario. Several issues contribute:
- jq -s (slurp mode) buffers the entire operatorhubio FBC response in
memory before processing, risking system errors on large catalogs
- catalog content queries run exactly once with no retry, so any
transient port-forward or network hiccup fails the step immediately
- bash() does not attach stderr to ExitError, making failures opaque
- with CatalogdHA, kubectl port-forward to the service deterministically
picks the same pod via GetFirstPod sorting; if that pod is not the
leader, it returns 404 (empty local cache) for every retry
Remove jq slurp mode so each JSON object is processed in constant
memory, prefixing filters with 'objects' to skip non-object values in
the FBC stream. Wrap CatalogContainsSomePackages, PackageHasSomeChannels,
and PackageHasSomeBundles in waitFor for retry on transient errors. Add
curl --compressed to handle gzip-encoded responses and --fail with
pipefail to detect HTTP errors. Resolve the catalogd leader pod via its
Lease and port-forward directly to it on the container port (8443),
falling back to the service when the lease cannot be read. Reset
port-forwards on query failure and re-establish dead ones via liveness
checks. Inject stderr into ExitError in bash() to match k8sClient
diagnostics. Log catalog query errors at V(0) so CI timeout failures
are diagnosable.
Co-authored-by: Claude <noreply@anthropic.com>
@openshift-botopenshift-bot added tide/merge-method-merge Denotes a PR that should use a standard merge by tide when it merges. kind/sync labels Aug 4, 2026
@openshift-ci-robotopenshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Aug 4, 2026
@openshift-botopenshift-bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 4, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@openshift-bot: This pull request explicitly references no jira issue.

Details

In response to this:

The downstream repository has been updated with the following following upstream commits:

DateCommitAuthorMessage
2026-08-03 18:07:27operator-framework/operator-controller@255f5dePredrag Knezevicfix: make demo e2e catalog queries resilient to transient failures (#2838)
2026-08-03 18:03:57operator-framework/operator-controller@0a6b0bedependabot[bot]🌱 Bump soupsieve from 2.8.4 to 2.9 (#2843)
2026-08-03 15:37:12operator-framework/operator-controller@fdaba96dependabot[bot]🌱 Bump github.com/klauspost/compress from 1.19.0 to 1.19.1 (#2845)
2026-08-03 15:34:31operator-framework/operator-controller@6145027dependabot[bot]🌱 Bump github.com/prometheus/client_golang (#2844)
2026-08-03 15:23:15operator-framework/operator-controller@d298851dependabot[bot]🌱 Bump regex from 2026.7.10 to 2026.7.19 (#2842)
2026-08-03 15:20:31operator-framework/operator-controller@689f632dependabot[bot]🌱 Bump platformdirs from 4.10.0 to 4.10.1 (#2841)
2026-08-03 15:17:13operator-framework/operator-controller@3240aa5dependabot[bot]🌱 Bump mkdocs-material from 9.7.6 to 9.7.7 (#2840)
2026-08-03 15:14:17operator-framework/operator-controller@0273129dependabot[bot]🌱 Bump actions/setup-python from 6.3.0 to 7.0.0 (#2839)
2026-07-31 16:38:07operator-framework/operator-controller@7db5d14dependabot[bot]🌱 Bump actions/checkout from 7.0.0 to 7.0.1 (#2837)
2026-07-29 15:39:34operator-framework/operator-controller@7ec6a0edependabot[bot]🌱 Bump actions/setup-go from 6.5.0 to 7.0.0 (#2836)

The vendor/ directory has been updated and the following commits were carried:

DateCommitAuthorMessage
2026-07-29 00:08:34openshift/operator-framework-operator-controller@2e7026cdtfranzUPSTREAM: <carry>: Add OpenShift specific files
2026-07-29 00:08:36openshift/operator-framework-operator-controller@2bb3a8aCamila MacedoUPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-07-29 00:08:37openshift/operator-framework-operator-controller@d1f3208Camila MacedoUPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-07-29 00:08:37openshift/operator-framework-operator-controller@b2fc6f3Camila MacedoUPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-07-29 00:08:38openshift/operator-framework-operator-controller@51b04ddTodd ShortUPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-07-29 00:08:39openshift/operator-framework-operator-controller@5fa95cdKui WangUPSTREAM: <carry>: support singleown cases in disconnected
2026-07-29 00:08:40openshift/operator-framework-operator-controller@135baedKui WangUPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-07-29 00:08:40openshift/operator-framework-operator-controller@ea99d97Camila MacedoUPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-07-29 00:08:41openshift/operator-framework-operator-controller@99bc51dTodd ShortUPSTREAM: <carry>: Update to new feature-gate options in helm
2026-07-29 00:08:42openshift/operator-framework-operator-controller@fe0de94Camila MacedoUPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-07-29 00:08:43openshift/operator-framework-operator-controller@4a92d7aCamila MacedoUPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-07-29 00:08:43openshift/operator-framework-operator-controller@8d66b27Kui WangUPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-07-29 00:08:44openshift/operator-framework-operator-controller@832f4a1Camila MacedoUPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-07-29 00:08:45openshift/operator-framework-operator-controller@639ef87Kui WangUPSTREAM: <carry>: Add [OTP] to migrated cases
2026-07-29 00:08:46openshift/operator-framework-operator-controller@5d89946Camila MacedoUPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-07-29 00:08:47openshift/operator-framework-operator-controller@aaa0df1Camila MacedoUPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-07-29 00:08:48openshift/operator-framework-operator-controller@8026046Camila MacedoUPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-07-29 00:08:49openshift/operator-framework-operator-controller@0a62a52Kui WangUPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-07-29 00:08:50openshift/operator-framework-operator-controller@8ce3742Jian ZhangUPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-07-29 00:08:51openshift/operator-framework-operator-controller@e965588Xia ZhaoUPSTREAM: <carry>: migrate clustercatalog case to ote
2026-07-29 00:08:51openshift/operator-framework-operator-controller@bde51deKui WangUPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-07-29 00:08:52openshift/operator-framework-operator-controller@b2fa498Todd ShortUPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-07-29 00:08:53openshift/operator-framework-operator-controller@b6100d0Xia ZhaoUPSTREAM: <carry>: migrate olmv1 QE cases
2026-07-29 00:08:53openshift/operator-framework-operator-controller@489171aKui WangUPSTREAM: <carry>: add agent for olmv1 qe cases
2026-07-29 00:08:54openshift/operator-framework-operator-controller@1f808b6Todd ShortUPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-07-29 00:08:55openshift/operator-framework-operator-controller@2014dfaRashmi GottipatiUPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-07-29 00:08:55openshift/operator-framework-operator-controller@33a90ebRashmi GottipatiUPSTREAM: <carry>: address review comments through addl prompts
2026-07-29 00:08:56openshift/operator-framework-operator-controller@ea7e63fRashmi GottipatiUPSTREAM: <carry>: addressing some more review comments
2026-07-29 00:08:57openshift/operator-framework-operator-controller@162219aRashmi GottipatiUPSTREAM: <carry>: remove DCO line
2026-07-29 00:08:57openshift/operator-framework-operator-controller@3f9cd8eBruno AndradeUPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-07-29 00:08:58openshift/operator-framework-operator-controller@78db4c7Bruno AndradeUPSTREAM: <carry>: update metadata
2026-07-29 00:08:59openshift/operator-framework-operator-controller@19cc3fcBruno AndradeUPSTREAM: <carry>: remove originalName
2026-07-29 00:08:59openshift/operator-framework-operator-controller@e89f1c2Jian ZhangUPSTREAM: <carry>: update 80458's timeout to 180s
2026-07-29 00:09:00openshift/operator-framework-operator-controller@4247a95Jian ZhangUPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-07-29 00:09:01openshift/operator-framework-operator-controller@4c8f275Catherine Chan-TseUPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-07-29 00:09:01openshift/operator-framework-operator-controller@e1bb13cPredrag KnezevicUPSTREAM: <carry>: Use oc client for running e2e tests
2026-07-29 00:09:02openshift/operator-framework-operator-controller@18c8babPredrag KnezevicUPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-07-29 00:09:03openshift/operator-framework-operator-controller@4ad733fKui WangUPSTREAM: <carry>: enhance case to make it more stable
2026-07-29 00:09:03openshift/operator-framework-operator-controller@bd4dd40Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-07-29 00:09:04openshift/operator-framework-operator-controller@857a3ebEvan HearneUPSTREAM: <carry>: move sa creation out of buildCurlJob()
2026-07-29 00:09:05openshift/operator-framework-operator-controller@a68dc2aEvan HearneUPSTREAM: <carry>: comment out delete service account
2026-07-29 00:09:06openshift/operator-framework-operator-controller@d899f37Evan HearneUPSTREAM: <carry>: move defercleanup for sa for LIFO
2026-07-29 00:09:06openshift/operator-framework-operator-controller@c54245cEvan HearneUPSTREAM: <carry>: add polling so job fully deleted before proceed
2026-07-29 00:09:07openshift/operator-framework-operator-controller@0a3a6a8Luke MeyerUPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redhat/add-service-account-curl-job"
2026-07-29 00:09:08openshift/operator-framework-operator-controller@6d4351fCamila MacedoUPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
2026-07-29 00:09:08openshift/operator-framework-operator-controller@477ed9cKui WangUPSTREAM: <carry>: config watchnamespace cases
2026-07-29 00:09:09openshift/operator-framework-operator-controller@ee080ddXia ZhaoUPSTREAM: <carry>: enhance ocp-79770
2026-07-29 00:09:10openshift/operator-framework-operator-controller@97ca4a9Kui WangUPSTREAM: <carry>: upgrade version support case
2026-07-29 00:09:10openshift/operator-framework-operator-controller@b37dffaPer Goncalves da SilvaUPSTREAM: <carry>: Remove installed condition check from auth preflight test
2026-07-29 00:09:11openshift/operator-framework-operator-controller@7003366Per Goncalves da SilvaUPSTREAM: <carry>: Add openshift/api dependency
2026-07-29 00:09:12openshift/operator-framework-operator-controller@147e323Per Goncalves da SilvaUPSTREAM: <carry>: Add boxcutter specific preflight auth test
2026-07-29 00:09:12openshift/operator-framework-operator-controller@cdec935Kui WangUPSTREAM: <carry>: adjust watchnamespace case based on change
2026-07-29 00:09:13openshift/operator-framework-operator-controller@03a3386Camila MacedoUPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root dir
2026-07-29 00:09:14openshift/operator-framework-operator-controller@adc763aBruno AndradeUPSTREAM: <carry>: add 83979 automation
2026-07-29 00:09:14openshift/operator-framework-operator-controller@183bc8dBruno AndradeUPSTREAM: <carry>: add 85889 automation
2026-07-29 00:09:15openshift/operator-framework-operator-controller@0d38d0dPer Goncalves da SilvaUPSTREAM: <carry>: Update test-operator startup script to fix pod probe endpoints
2026-07-29 00:09:16openshift/operator-framework-operator-controller@b5d0f94Per Goncalves da SilvaUPSTREAM: <carry>: Fix up own-namespace invalid configuration test
2026-07-29 00:09:16openshift/operator-framework-operator-controller@158ec9cCamila MacedoUPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles instead of openshift-pipelines-operator-rh
2026-07-29 00:09:17openshift/operator-framework-operator-controller@f8602b6Kui WangUPSTREAM: <carry>: adjust sa and permission test cases per new change from boxcutterruntime
2026-07-29 00:09:18openshift/operator-framework-operator-controller@c5c79acCamila MacedoUPSTREAM: <carry>: Update OCP catalogs to v4.22
2026-07-29 00:09:19openshift/operator-framework-operator-controller@7828832Camila MacedoUPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and dependencies
2026-07-29 00:09:20openshift/operator-framework-operator-controller@276fbbcJian ZhangUPSTREAM: <carry>: fix 83026 for TP cluster
2026-07-29 00:09:21openshift/operator-framework-operator-controller@b6bda60Kui WangUPSTREAM: <carry>: serviceAccount validation unified across all runtimes
2026-07-29 00:09:22openshift/operator-framework-operator-controller@3ec750eStephen BenjaminUPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
2026-07-29 00:09:22openshift/operator-framework-operator-controller@03fa5c0Camila MacedoUPSTREAM: <carry>: Increase install timeout and add diagnostic logging for CE install tests
2026-07-29 00:09:23openshift/operator-framework-operator-controller@ec0fc4fEvan HearneUPSTREAM: <carry>: add service account to curl job
2026-07-29 00:09:23openshift/operator-framework-operator-controller@48a0c82Jian ZhangUPSTREAM: <carry>: update OCP-75441 to support multi-arch
2026-07-29 00:09:24openshift/operator-framework-operator-controller@5126b61Kui WangUPSTREAM: <carry>: deployment config cases
2026-07-29 00:09:25openshift/operator-framework-operator-controller@dbd3c66Todd ShortUPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
2026-07-29 00:09:26openshift/operator-framework-operator-controller@0d57d47Todd ShortUPSTREAM: <carry>: Update openshift/api and client-go
2026-07-29 00:09:26openshift/operator-framework-operator-controller@6d5ebf2Camila MacedoUPSTREAM: <carry>: Add boxcutter tests
2026-07-29 00:09:27openshift/operator-framework-operator-controller@08d0f6fXia ZhaoUPSTREAM: <carry>: enhance QE cases
2026-07-29 00:09:28openshift/operator-framework-operator-controller@aa7522eDaniel FranzUPSTREAM: <carry>: Update quay-operator version to one containing arm64 support
2026-07-29 00:09:28openshift/operator-framework-operator-controller@498338bKui WangUPSTREAM: <carry>: verify volume/volumeMount override
2026-07-29 00:09:29openshift/operator-framework-operator-controller@382cdb8Jian ZhangUPSTREAM: <carry>: Add long-duration test script and documents
2026-07-29 00:09:30openshift/operator-framework-operator-controller@8191908Todd ShortUPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
2026-07-29 00:09:31openshift/operator-framework-operator-controller@34c2a3dCamila MacedoUPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSet in OTE tests
2026-07-29 00:09:32openshift/operator-framework-operator-controller@90bc5efCamila MacedoUPSTREAM: <carry>: Skip incompatible operator test when Boxcutter uses ClusterObjectSet
2026-07-29 00:09:32openshift/operator-framework-operator-controller@733b829Bruno AndradeUPSTREAM: <carry>: add ocp-87557
2026-07-29 00:09:33openshift/operator-framework-operator-controller@87a2a7fFrancesco GiudiciUPSTREAM: <carry>: Add fgiudici as reviewer
2026-07-29 00:09:34openshift/operator-framework-operator-controller@93fd425Camila MacedoUPSTREAM: <carry>: Remove skip for incompatible operator check after rename of CER
2026-07-29 00:09:34openshift/operator-framework-operator-controller@b3d9234Kui WangUPSTREAM: <carry>: Test empty affinity erasure and cleanup
2026-07-29 00:09:35openshift/operator-framework-operator-controller@093e927Camila MacedoUPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in preflight test
2026-07-29 00:09:36openshift/operator-framework-operator-controller@28f4992Camila MacedoUPSTREAM: <carry>: Expand OTE docs with more comprehensive details
2026-07-29 00:09:36openshift/operator-framework-operator-controller@cc35128Todd ShortUPSTREAM: <carry>: Disable upstream TLSProfile tests
2026-07-29 00:09:37openshift/operator-framework-operator-controller@759899bCamila MacedoUPSTREAM: <carry>: OTE: Simplify by remove option to configure tests to run outside of OCP
2026-07-29 00:09:38openshift/operator-framework-operator-controller@2fb21b1Camila MacedoUPSTREAM: <carry>: OTE - Make OTE local output easier to read
2026-07-29 00:09:39openshift/operator-framework-operator-controller@8267e25Joe LanfordUPSTREAM: <carry>: remove dead e2e registry push job and related variables
2026-07-29 00:09:40openshift/operator-framework-operator-controller@7ed9698Todd ShortUPSTREAM: <carry>: OCPBUGS-62517: Set replicas=1, PDB, and pod anti-affinity for HA topology
2026-07-29 00:09:41openshift/operator-framework-operator-controller@c238f0fTodd ShortUPSTREAM: <carry>: fix(test): drop blocking namespace-deletion wait between both-watch-modes scenarios
2026-07-29 00:09:42openshift/operator-framework-operator-controller@5739a9eTodd ShortUPSTREAM: <carry>: Fix downstream e2e test invocation
2026-07-29 00:09:43openshift/operator-framework-operator-controller@0831969Joe LanfordUPSTREAM: <carry>: Delete openshift/registry.Dockerfile
2026-07-29 00:09:44openshift/operator-framework-operator-controller@9b50613Todd ShortUPSTREAM: <carry>: Remove test-experimenal-e2e
2026-07-29 00:09:45openshift/operator-framework-operator-controller@3785c88Camila MacedoUPSTREAM: <carry>: Update readme Default Catalog Tests
2026-07-29 00:09:46openshift/operator-framework-operator-controller@ecaf2c6Todd ShortUPSTREAM: <carry>: add OLMv1 topology-based deployment scaling e2e test
2026-07-29 00:09:48openshift/operator-framework-operator-controller@a002887Todd ShortUPSTREAM: <carry>: Update dockerfiles to use golang-1.26-release-4.23 builders
2026-07-29 00:09:49openshift/operator-framework-operator-controller@4b5d24dAOS Automation Release TeamUPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-operator-controller.yml
2026-07-29 00:09:50openshift/operator-framework-operator-controller@90a3ae9AOS Automation Release TeamUPSTREAM: <carry>: Updating ose-olm-catalogd-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-catalogd.yml
2026-07-29 00:09:51openshift/operator-framework-operator-controller@559ef81Todd ShortUPSTREAM: <carry>: Update catalogs for 4.23/5.0
2026-07-29 00:09:53openshift/operator-framework-operator-controller@ef82bbaPer G. da SilvaUPSTREAM: <carry>: Remove HelmChartSupport feature gate from experimental manifests
2026-07-29 00:09:54openshift/operator-framework-operator-controller@4fd2ca9Todd ShortUPSTREAM: <carry>: test: add allow-case for operator maxOCPVersion > cluster version
2026-07-29 00:09:55openshift/operator-framework-operator-controller@a192469Daniel FranzUPSTREAM: <carry>: Add OLMv1 progress deadline QE tests
2026-07-29 00:09:56openshift/operator-framework-operator-controller@e006f96Todd ShortUPSTREAM: <carry>: Remove stale reviewers/approvers, add trgeiger
2026-07-29 00:09:57openshift/operator-framework-operator-controller@6856d00Daniel FranzUPSTREAM: <carry>: Remove openshift/ e2e related to deprecated ServiceAccount usage in ClusterExtension API, Synthetic Permissions, and PreFlight Admissions
2026-07-29 00:09:58openshift/operator-framework-operator-controller@9f51d6eTodd ShortUPSTREAM: <carry>: fix(test): update PolarionID:87224 for 4.23/5.0 upgrade boundary

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-botopenshift-bot added the lgtm Indicates that a PR is ready to be merged. label Aug 4, 2026
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

The PR adds Fluent Bit log persistence for E2E support bundles, improves catalog port-forward recovery and query retries, and updates Go, Python, and repository ownership metadata.

Changes

E2E observability and catalog reliability

Layer / File(s)Summary
Catalog connection and query recovery
test/e2e/steps/demo_steps.go
Catalog checks resolve leader pods, validate and reset port forwards, preserve subprocess stderr, detect HTTPS and HTTP failures, and retry catalog queries.
Fluent Bit deployment and support-bundle collection
Makefile, testdata/fluentbit/values.yaml, test/e2e/support-bundle.yaml
The E2E workflow deploys Fluent Bit. Fluent Bit persists operator-controller and catalogd logs for support-bundle collection.
Dependency version updates
go.mod, openshift/tests-extension/go.mod, requirements.txt
Go and Python dependency pins use updated versions.

Repository ownership metadata

Layer / File(s)Summary
OWNERS alias membership
OWNERS_ALIASES
The olmv1-approvers and olmv1-reviewers memberships are revised.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
participant CatalogChecks
participant KubernetesAPI
participant PortForward
participant Catalogd
CatalogChecks->>KubernetesAPI: Resolve catalogd leader lease
KubernetesAPI-->>CatalogChecks: Return leader pod or service fallback
CatalogChecks->>PortForward: Validate or start port forward
PortForward->>Catalogd: Check HTTPS health
Catalogd-->>PortForward: Return health response
CatalogChecks->>Catalogd: Query catalog data
Catalogd-->>CatalogChecks: Return data or HTTP failure
CatalogChecks->>PortForward: Reset failed forward
CatalogChecks->>Catalogd: Retry catalog query
Loading

Suggested reviewers:joelanford, pedjak


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (2 errors, 3 warnings)

Check nameStatusExplanationResolution
Container-Privileges❌ ErrorThe added Fluent Bit values leave securityContext empty; chart 0.57.9 emits no security context and image 5.0.9 has no USER, so the DaemonSet runs as root with default privilege escalation.Set explicit securityContext values: privileged=false, allowPrivilegeEscalation=false, drop capabilities, and a non-root UID where compatible; document and isolate any unavoidable root requirement.
No-Sensitive-Data-In-Logs❌ ErrorThe PR persists unfiltered operator/catalogd logs and copies them into support bundles; catalogd logs include request host, username, URI, and full ClusterCatalog objects.Add redaction and allowlisted fields before persistence; exclude credentials, query data, object contents, usernames, and internal host identifiers from logs and support bundles.
Docstring Coverage⚠️ WarningDocstring coverage is 11.11% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Topology-Aware Scheduling Compatibility⚠️ WarningThe synchronization adds OpenShift deployments with required nodeSelectors for master/control-plane labels and no ControlPlaneTopology handling; HyperShift pods can remain Pending.Add topology-aware scheduling. Avoid control-plane selectors for External topology, exclude arbiter nodes, and validate SNO, TNF, TNA, and HyperShift deployments.
Ipv6 And Disconnected Network Test Compatibility⚠️ Warninge2e-run now pulls the Fluent Bit chart from public ghcr.io and support-bundle.yaml uses unqualified busybox:1.36; demo_steps.go also builds HTTPS URLs with %s.Use internal mirrors for the chart and image, or skip disconnected runs; then run /payload-job periodic-ci-openshift-release-master-nightly-4.22-e2e-metal-ipi-ovn-ipv6.
✅ Passed checks (10 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names✅ PassedThe PR adds no Ginkgo title declarations. The only changed non-vendor Go file has no It/Describe/Context/When calls; existing dynamic titles are unchanged from origin/main.
Test Structure And Quality✅ PassedThe PR changes no Ginkgo test files; the only changed Go test-area file registers Godog steps, and the other changes are YAML and dependencies.
Microshift Test Compatibility✅ PassedNo new or modified Ginkgo e2e tests are present; the only changed Go e2e file is a Godog step file with no Ginkgo imports or declarations.
Single Node Openshift (Sno) Test Compatibility✅ PassedThe PR adds no Ginkgo e2e tests or test declarations; it only modifies catalog step helpers and support-bundle/Fluent Bit configuration, so SNO assumptions do not apply.
Ote Binary Stdout Contract✅ Passedmain() has no stdout writes; OTE configureGinkgo redirects GinkgoWriter to os.Stderr, and suite diagnostics use GinkgoWriter. Remaining fmt.Printf calls are test helpers or dev-only commands.
No-Weak-Crypto✅ PassedNo added weak-crypto APIs, algorithms, custom crypto, or secret comparisons were found; Blowfish metadata and existing 3DES/TLS references are unchanged from main.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the pull request as a synchronization of downstream changes from upstream repositories.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@requirements.txt`:
- Line 17: Update requirements.txt so every resolved distribution, including
mkdocs-material, has a pinned artifact hash, and update the installation command
in Makefile.venv to use pip’s --require-hashes option when installing
requirements.txt.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 71f666f1-6bb6-4732-8a2f-5ff4651ad7c1

📥 Commits

Reviewing files that changed from the base of the PR and between cf65286 and 6ed83d9.

⛔ Files ignored due to path filters (63)
  • go.sum is excluded by !**/*.sum
  • openshift/tests-extension/go.sum is excluded by !**/*.sum
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil/header/header.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_go116.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_latest.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/counter.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/desc.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/expvar_collector.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/gauge.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/go_collector_go116.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/go_collector_latest.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/histogram.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/internal/difflib.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/labels.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/metric.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/process_collector_darwin.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/process_collector_windows.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/http.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_client.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_server.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/option.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/registry.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/summary.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/timer.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/vec.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/wrap.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/net_wireless.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/proc_cgroup.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/modules.txt is excluded by !**/vendor/**
  • vendor/github.com/klauspost/compress/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/flate/inflate_gen.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/snappy.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/api/client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/api/prometheus/v1/api.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil/header/header.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/counter.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/desc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/expvar_collector.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/gauge.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/histogram.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/internal/difflib.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/labels.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/metric.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_darwin.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/http.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_server.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/option.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/registry.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/summary.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/timer.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/vec.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/wrap.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/net_wireless.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/proc_cgroup.go is excluded by !**/vendor/**, !vendor/**
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (4)
  • go.mod
  • openshift/tests-extension/go.mod
  • requirements.txt
  • test/e2e/steps/demo_steps.go

Comment threadrequirements.txt
mergedeep==1.3.4
mkdocs==1.6.1
mkdocs-material==9.7.6
mkdocs-material==9.7.7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bashset -euo pipefail
echo"Hash entries in requirements files:"
rg -n --glob 'requirements*.txt' -- '--hash='.||trueecho"Hash enforcement in repository configuration:"
rg -n --hidden --glob '!**/.git/**' -- 'pip .*--require-hashes|--require-hashes'.||true

Repository: openshift/operator-framework-operator-controller

Length of output: 268


🏁 Script executed:

#!/bin/bashset -euo pipefail
echo"Tracked requirement files:"
git ls-files '*requirements*.txt''*Pipfile*''pyproject.toml''package*.json''go.mod''go.sum''Cargo.toml''Gemfile*''pom.xml''build.gradle*'echoecho"requirements.txt context:"if [ -f requirements.txt ];then
cat -n requirements.txt
fiechoecho"Installation and CI references:"
rg -n --hidden --glob '!**/.git/**' \
'(^|[[:space:]])(pip|python[0-9.]* -m pip|uv|poetry)[[:space:]]+[^#\n]*(install|sync)|requirements\.txt|--require-hashes|pip-tools|pip-compile' \
.||trueechoecho"Repository metadata and workflows:"
git ls-files '.github/workflows/*''Makefile''tox.ini''setup.cfg''pyproject.toml''Dockerfile*'| sort

Repository: openshift/operator-framework-operator-controller

Length of output: 3343


🌐 Web query:

mkdocs-material 9.7.7 PyPI release hashes known vulnerabilities OSV

💡 Result:

The mkdocs-material package version 9.7.7 was released on PyPI on July 17, 2026 [1][2][3]. Regarding vulnerabilities, version 9.7.7 was specifically released to address a DOM-based cross-site scripting (XSS) vulnerability in the optional search.suggest feature [4][3]. This vulnerability, tracked as GHSA-xvg9-69gf-fjrf, affected versions 7.2.0 through 9.7.6 [4]. Users of these older versions are advised to upgrade to 9.7.7 or later, or disable the search.suggest feature if upgrading is not possible [4]. There is no CVE assigned to this issue [4]. Regarding hashes for version 9.7.7, PyPI provides these directly on the package files page. You can verify the integrity of the downloaded file by comparing its SHA-256 hash against the values provided in the "Download files" section for the 9.7.7 release on the official PyPI project page [5][2]. Top results: [5] https://pypi.org/project/mkdocs-material/9.7.7/ [1] https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7 [2] https://pypi.org/project/mkdocs-material/ [4] GHSA-xvg9-69gf-fjrf [3] https://squidfunk.github.io/mkdocs-material/changelog/

Citations:


🏁 Script executed:

#!/bin/bashset -euo pipefail
echo"Makefile.venv installation logic:"
sed -n '70,105p;210,245p' Makefile.venv
echoecho"References to the virtual-environment targets:"
rg -n --hidden --glob '!**/.git/**' \
'Makefile\.venv|REQUIREMENTS_TXT|venv|make .*venv|\.venv|pip install' \
Makefile* .github 2>/dev/null ||trueechoecho"Tracked workflow and build files:"
git ls-files | rg '(^|/)(\.github/workflows/|Makefile[^/]*$|Dockerfile[^/]*$|requirements[^/]*\.txt$)'| sort
echoecho"Hash support for the reviewed package:"
python3 - <<'PY'import jsonimport urllib.requesturl = "https://pypi.org/pypi/mkdocs-material/9.7.7/json"with urllib.request.urlopen(url, timeout=10) as response: data = json.load(response)for item in data["urls"]: print(item["filename"], item["packagetype"], item["digests"].get("sha256"))PY

Repository: openshift/operator-framework-operator-controller

Length of output: 11883


Add hashes to every resolved distribution and enforce them in Makefile.venv. Use pip --require-hashes when installing requirements.txt. Version pins alone do not verify downloaded artifacts.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@requirements.txt` at line 17, Update requirements.txt so every resolved
distribution, including mkdocs-material, has a pinned artifact hash, and update
the installation command in Makefile.venv to use pip’s --require-hashes option
when installing requirements.txt.

Source: Path instructions

Bumps [platformdirs](https://github.com/tox-dev/platformdirs) from 4.10.1 to 4.11.0.
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.10.1...4.11.0)
---
updated-dependencies:
- dependency-name: platformdirs
dependency-version: 4.11.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@coderabbitai

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@openshift-ciopenshift-ciBot removed the lgtm Indicates that a PR is ready to be merged. label Aug 5, 2026

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/e2e/steps/demo_steps.go`:
- Around line 175-177: Replace the shell-interpolated script in the catalog
query step with separate exec.CommandContext invocations for curl and jq,
preserving pipefail-equivalent error handling. Path-escape catalogName when
constructing the curl URL, and pass packageName to jq via --arg rather than
interpolating it into jqFilter; update the surrounding query logic in the
relevant step function accordingly.
- Around line 137-150: Update catalogPortForwardAlive to return false when the
probe receives a non-2xx HTTP status, and propagate a false result if
resp.Body.Close() returns an error; only return true after both the request
succeeds with a successful status and the response body closes successfully.
- Line 133: Update the Info log in the leader-resolution flow to report only
that resolution succeeded; remove the holder and podName identity fields from
the logger.Info call while preserving the existing success log context.
- Around line 137-145: Update catalogPortForwardAlive to accept a scenario
context, pass ctx from both callers, and create the health request with
http.NewRequestWithContext before executing it via client.Do. Preserve the
existing URL, timeout, and response-check behavior while ensuring cancellation
interrupts the request.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 0e0c75f8-a7fc-4134-8e5e-67b844848517

📥 Commits

Reviewing files that changed from the base of the PR and between cf65286 and a17ced3.

⛔ Files ignored due to path filters (63)
  • go.sum is excluded by !**/*.sum
  • openshift/tests-extension/go.sum is excluded by !**/*.sum
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil/header/header.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_go116.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_latest.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/counter.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/desc.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/expvar_collector.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/gauge.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/go_collector_go116.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/go_collector_latest.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/histogram.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/internal/difflib.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/labels.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/metric.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/process_collector_darwin.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/process_collector_windows.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/http.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_client.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_server.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/promhttp/option.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/registry.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/summary.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/timer.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/vec.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/client_golang/prometheus/wrap.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/net_wireless.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/proc_cgroup.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/modules.txt is excluded by !**/vendor/**
  • vendor/github.com/klauspost/compress/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/flate/inflate_gen.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/snappy.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/api/client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/api/prometheus/v1/api.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil/header/header.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/counter.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/desc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/expvar_collector.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/gauge.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/histogram.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/internal/difflib.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/labels.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/metric.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_darwin.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/http.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_server.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/option.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/registry.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/summary.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/timer.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/vec.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/wrap.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/net_wireless.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/proc_cgroup.go is excluded by !**/vendor/**, !vendor/**
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (4)
  • go.mod
  • openshift/tests-extension/go.mod
  • requirements.txt
  • test/e2e/steps/demo_steps.go
🚧 Files skipped from review as they are similar to previous changes (3)
  • openshift/tests-extension/go.mod
  • go.mod
  • requirements.txt

if podName == "" {
return "", fmt.Errorf("catalogd leader lease has empty holderIdentity")
}
logger.Info("Resolved catalogd leader pod", "holder", holder, "pod", podName)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bashset -eu
file='test/e2e/steps/demo_steps.go'printf'%s\n''--- outline ---'
ast-grep outline "$file"2>/dev/null ||trueprintf'%s\n''--- target context ---'
sed -n '105,145p'"$file"printf'%s\n''--- holder and podName references ---'
rg -n -C 3 '\b(holder|podName)\b|Resolved catalogd leader pod|logger\.'"$file"printf'%s\n''--- logger setup in the file ---'
rg -n -C 3 'logr|klog|NewLogger|SetOutput|logger\s*='"$file"||true

Repository: openshift/operator-framework-operator-controller

Length of output: 7148


🏁 Script executed:

#!/bin/bashset -eu
printf'%s\n''--- package and logger declarations ---'
rg -n -C 4 '(^package |logger\s*=|var\s+logger|func\s+logger|NewLogger|SetLogger|logr\.|klog\.)' test/e2e/steps --glob '*.go'printf'%s\n''--- logger imports and package context ---'
sed -n '1,45p' test/e2e/steps/demo_steps.go
printf'%s\n''--- bounded behavioral verifier ---'
python3 - <<'PY'from pathlib import Pathimport rep = Path("test/e2e/steps/demo_steps.go")s = p.read_text()m = re.search( r'holder,\s*err\s*:=\s*k8sClient\(ctx,\s*"get",\s*"lease".*?' r'holder\s*=\s*strings\.TrimSpace\(holder\).*?' r'podName\s*:=\s*holder.*?' r'if idx := strings\.LastIndex\(holder, "_"\); idx >= 0 \{\s*' r'podName = holder\[:idx\]\s*\}.*?' r'logger\.Info\("Resolved catalogd leader pod",\s*"holder",\s*holder,\s*"pod",\s*podName\)', s, re.S,)print("leader_lease_to_log_path:", bool(m))print("returns_logged_pod_name:", bool(re.search(r'return fmt\.Sprintf\("pod/%s", podName\)', s)))print("info_log_contains_holder_and_pod:", '"holder", holder, "pod", podName' in s)PY

Repository: openshift/operator-framework-operator-controller

Length of output: 4814


Information Disclosure (CWE-200): Exposure of Sensitive Information to an Unauthorized Actor

Reachability: Internal · Exploitability: Difficult

Remove leader identities from the Info log.

holder comes from the catalogd leader Lease, and podName is derived from it. Log only that leader resolution succeeded because CI logs can expose internal pod hostnames.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@test/e2e/steps/demo_steps.go` at line 133, Update the Info log in the
leader-resolution flow to report only that resolution succeeded; remove the
holder and podName identity fields from the logger.Info call while preserving
the existing success log context.

Source: Coding guidelines

Comment on lines +137 to +145
func catalogPortForwardAlive(addr string) bool {
client := &http.Client{
Timeout: 3 * time.Second,
Transport: &http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, //nolint:gosec
DialContext: (&net.Dialer{Timeout: 2 * time.Second}).DialContext,
},
}
resp, err := client.Get(fmt.Sprintf("https://%s/", addr))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bashset -euo pipefail
# Find every caller that must pass the scenario context after the signature change.
rg -n -C 4 --type go '\bcatalogPortForwardAlive\s*\(' test/e2e

Repository: openshift/operator-framework-operator-controller

Length of output: 1876


🏁 Script executed:

#!/usr/bin/env bashset -euo pipefail
printf'%s\n''--- demo_steps.go ---'
sed -n '1,180p' test/e2e/steps/demo_steps.go
printf'%s\n''--- waitFor definition and callers ---'
rg -n -C 8 --type go '\bfunc waitFor\b|\bwaitFor\s*\(' test/e2e

Repository: openshift/operator-framework-operator-controller

Length of output: 50404


🏁 Script executed:

#!/usr/bin/env bashset -euo pipefail
tmp="$(mktemp --suffix=.go)"trap'rm -f "$tmp"' EXIT
cat >"$tmp"<<'GO'package mainimport (	"context"	"fmt"	"net/http"	"net/http/httptest"	"time")func main() {	seenCanceled := make(chan bool, 2)	server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { select { case <-r.Context().Done(): seenCanceled <- true case <-time.After(500 * time.Millisecond): seenCanceled <- false }	}))	defer server.Close()	outer, cancel := context.WithCancel(context.Background())	done := make(chan error, 1)	go func() { _, err := (&http.Client{Timeout: time.Second}).Get(server.URL) done <- err	}()	cancel()	select {	case <-seenCanceled: fmt.Println("client.Get propagated outer cancellation: true")	case <-time.After(100 * time.Millisecond): fmt.Println("client.Get propagated outer cancellation: false")	}	<-done	requestCtx, requestCancel := context.WithCancel(context.Background())	req, err := http.NewRequestWithContext(requestCtx, http.MethodGet, server.URL, nil)	if err != nil { panic(err)	}	done = make(chan error, 1)	go func() { _, err := (&http.Client{Timeout: time.Second}).Do(req) done <- err	}()	requestCancel()	select {	case propagated := <-seenCanceled: fmt.Printf("NewRequestWithContext propagated cancellation: %v\n", propagated)	case <-time.After(100 * time.Millisecond): fmt.Println("NewRequestWithContext propagated cancellation: false")	}	<-done}GO
go run "$tmp"

Repository: openshift/operator-framework-operator-controller

Length of output: 298


🏁 Script executed:

#!/usr/bin/env bashset -euo pipefail
tmp="$(mktemp --suffix=.go)"trap'rm -f "$tmp"' EXIT
cat >"$tmp"<<'GO'package mainimport (	"context"	"fmt"	"net/http"	"net/http/httptest"	"time")func main() {	seenCanceled := make(chan bool, 2)	server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { select { case <-r.Context().Done(): seenCanceled <- true case <-time.After(500 * time.Millisecond): seenCanceled <- false }	}))	defer server.Close()	outer, cancel := context.WithCancel(context.Background())	done := make(chan error, 1)	go func() { _, err := (&http.Client{Timeout: time.Second}).Get(server.URL) done <- err	}()	cancel()	select {	case <-seenCanceled: fmt.Println("client.Get propagated outer cancellation: true")	case <-time.After(100 * time.Millisecond): fmt.Println("client.Get propagated outer cancellation: false")	}	<-done	_ = outer	requestCtx, requestCancel := context.WithCancel(context.Background())	req, err := http.NewRequestWithContext(requestCtx, http.MethodGet, server.URL, nil)	if err != nil { panic(err)	}	done = make(chan error, 1)	go func() { _, err := (&http.Client{Timeout: time.Second}).Do(req) done <- err	}()	requestCancel()	select {	case propagated := <-seenCanceled: fmt.Printf("NewRequestWithContext propagated cancellation: %v\n", propagated)	case <-time.After(100 * time.Millisecond): fmt.Println("NewRequestWithContext propagated cancellation: false")	}	<-done}GO
CGO_ENABLED=0 go run "$tmp"

Repository: openshift/operator-framework-operator-controller

Length of output: 287


🏁 Script executed:

#!/usr/bin/env bashset -euo pipefail
tmp="$(mktemp --suffix=.go)"trap'rm -f "$tmp"' EXIT
cat >"$tmp"<<'GO'package mainimport (	"context"	"fmt"	"net/http"	"net/http/httptest"	"time")func main() {	ready := make(chan struct{})	canceled := make(chan struct{})	server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { close(ready) <-r.Context().Done() close(canceled)	}))	defer server.Close()	ctx1, cancel1 := context.WithCancel(context.Background())	go func() { _, _ = (&http.Client{Timeout: time.Second}).Get(server.URL)	}()	select {	case <-ready:	case <-time.After(time.Second): panic("client.Get did not reach the handler")	}	cancel1()	select {	case <-canceled: fmt.Println("client.Get propagated an unrelated context cancellation: true")	case <-time.After(100 * time.Millisecond): fmt.Println("client.Get propagated an unrelated context cancellation: false")	}	_ = ctx1	ready = make(chan struct{})	canceled = make(chan struct{})	ctx2, cancel2 := context.WithCancel(context.Background())	req, err := http.NewRequestWithContext(ctx2, http.MethodGet, server.URL, nil)	if err != nil { panic(err)	}	go func() { _, _ = (&http.Client{Timeout: time.Second}).Do(req)	}()	select {	case <-ready:	case <-time.After(time.Second): panic("context-bound request did not reach the handler")	}	cancel2()	select {	case <-canceled: fmt.Println("NewRequestWithContext propagated cancellation: true")	case <-time.After(time.Second): fmt.Println("NewRequestWithContext propagated cancellation: false")	}}GO
CGO_ENABLED=0 go run "$tmp"

Repository: openshift/operator-framework-operator-controller

Length of output: 314


Bind the health request to the scenario context.

catalogPortForwardAlive does not use the scenario context, so cancellation cannot stop its HTTP request before the client timeout. Pass ctx from both callers, create the request with http.NewRequestWithContext, and call client.Do.

🧰 Tools
🪛 ast-grep (0.45.0)

[warning] 139-142: This http.Transport is configured with a tls.Config that sets InsecureSkipVerify: true, which disables TLS certificate verification for every request made through the resulting http.Client. The server's certificate chain and host name are not validated, exposing the connection to man-in-the-middle attacks. Remove InsecureSkipVerify (or set it to false) and supply a proper RootCAs pool if you need to trust custom certificates.
Context: http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, //nolint:gosec
DialContext: (&net.Dialer{Timeout: 2 * time.Second}).DialContext,
}
Note: [CWE-295] Improper Certificate Validation.

(http-transport-tls-skip-verify-go)


[warning] 140-140: MinVersionis missing from this TLS configuration. By default, TLS 1.2 is currently used as the minimum when acting as a client, and TLS 1.0 when acting as a server. General purpose web applications should default to TLS 1.3 with all other protocols disabled. Only where it is known that a web server must support legacy clients with unsupported an insecure browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0 to provide support. AddMinVersion: tls.VersionTLS13' to the TLS configuration to bump the minimum version to TLS 1.3.
Context: tls.Config{InsecureSkipVerify: true}
Note: [CWE-327]: Use of a Broken or Risky Cryptographic Algorithm [OWASP A03:2017]: Sensitive Data Exposure [OWASP A02:2021]: Cryptographic Failures

(missing-ssl-minversion-go)

🪛 OpenGrep (1.26.0)

[ERROR] 141-141: TLS certificate verification is disabled via InsecureSkipVerify. This allows man-in-the-middle attacks. Remove InsecureSkipVerify or set it to false.

(coderabbit.tls.go-insecure-skip-verify)


[ERROR] 141-141: TLS certificate verification is disabled via InsecureSkipVerify. This allows man-in-the-middle attacks. Remove InsecureSkipVerify or set it to false.

(coderabbit.tls.go-insecure-skip-verify)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@test/e2e/steps/demo_steps.go` around lines 137 - 145, Update
catalogPortForwardAlive to accept a scenario context, pass ctx from both
callers, and create the health request with http.NewRequestWithContext before
executing it via client.Do. Preserve the existing URL, timeout, and
response-check behavior while ensuring cancellation interrupts the request.

Source: Path instructions

Comment on lines +137 to +150
func catalogPortForwardAlive(addr string) bool {
client := &http.Client{
Timeout: 3 * time.Second,
Transport: &http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, //nolint:gosec
DialContext: (&net.Dialer{Timeout: 2 * time.Second}).DialContext,
},
}
resp, err := client.Get(fmt.Sprintf("https://%s/", addr))
if err != nil {
return false
}
resp.Body.Close()
return true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bashset -eu
file="test/e2e/steps/demo_steps.go"
sed -n '100,175p'"$file"printf'\n-- related symbols --\n'
rg -n -C 4 'catalogPortForwardAlive|waitFor|non-leader|404|StatusCode' test/e2e

Repository: openshift/operator-framework-operator-controller

Length of output: 43094


🏁 Script executed:

#!/bin/bashset -eu
cat <<'GO' >/tmp/http_probe_check.gopackage mainimport (	"fmt"	"net/http"	"net/http/httptest")func main() {	for _, code := range []int{http.StatusOK, http.StatusNotFound, http.StatusInternalServerError} { server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { w.WriteHeader(code) })) resp, err := http.Get(server.URL) fmt.Printf("status=%d err_nil=%t response_non_nil=%t\n", code, err == nil, resp != nil) if resp != nil { _ = resp.Body.Close() } server.Close()	}}GOifcommand -v go >/dev/null 2>&1;then
go run /tmp/http_probe_check.go
elseecho"go is unavailable; source-level result: net/http returns a response with nil error for HTTP status responses, including 404"fi

Repository: openshift/operator-framework-operator-controller

Length of output: 298


🌐 Web query:

Go net/http Client.Get returns error only on client policy or protocol failure HTTP 404 response documentation

💡 Result:

The Go net/http Client.Get method (and the underlying Client.Do) does not return an error for HTTP status codes, including HTTP 404 (Not Found) [1][2]. An HTTP 404 response is considered a successful HTTP transaction from the perspective of the client, meaning the request was successfully sent and a valid HTTP response was received [1][3]. According to the official Go documentation, an error is only returned by Client.Get if [1][4]: - There is a failure in the client's policy, such as when the CheckRedirect function returns an error [5][4]. - There is a failure to complete the HTTP request due to low-level issues, such as network connectivity problems, protocol errors, or request timeouts [1][5]. When the returned error is nil, the response object (resp) is non-nil, and the caller is responsible for checking the resp.StatusCode to handle specific HTTP status codes like 404 [1][2]. Example pattern for checking 404: resp, err:= http.Get("http://example.com/not-found") if err!= nil { // Handle network, protocol, or policy errors return err } defer resp.Body.Close if resp.StatusCode == http.StatusNotFound { // Handle 404 specifically return fmt.Errorf("resource not found") }

Citations:


Reject failed HTTP responses in the port-forward probe.

Return false for non-2xx responses. Return false when resp.Body.Close() fails.

🧰 Tools
🪛 ast-grep (0.45.0)

[warning] 139-142: This http.Transport is configured with a tls.Config that sets InsecureSkipVerify: true, which disables TLS certificate verification for every request made through the resulting http.Client. The server's certificate chain and host name are not validated, exposing the connection to man-in-the-middle attacks. Remove InsecureSkipVerify (or set it to false) and supply a proper RootCAs pool if you need to trust custom certificates.
Context: http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, //nolint:gosec
DialContext: (&net.Dialer{Timeout: 2 * time.Second}).DialContext,
}
Note: [CWE-295] Improper Certificate Validation.

(http-transport-tls-skip-verify-go)


[warning] 140-140: MinVersionis missing from this TLS configuration. By default, TLS 1.2 is currently used as the minimum when acting as a client, and TLS 1.0 when acting as a server. General purpose web applications should default to TLS 1.3 with all other protocols disabled. Only where it is known that a web server must support legacy clients with unsupported an insecure browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0 to provide support. AddMinVersion: tls.VersionTLS13' to the TLS configuration to bump the minimum version to TLS 1.3.
Context: tls.Config{InsecureSkipVerify: true}
Note: [CWE-327]: Use of a Broken or Risky Cryptographic Algorithm [OWASP A03:2017]: Sensitive Data Exposure [OWASP A02:2021]: Cryptographic Failures

(missing-ssl-minversion-go)

🪛 OpenGrep (1.26.0)

[ERROR] 141-141: TLS certificate verification is disabled via InsecureSkipVerify. This allows man-in-the-middle attacks. Remove InsecureSkipVerify or set it to false.

(coderabbit.tls.go-insecure-skip-verify)


[ERROR] 141-141: TLS certificate verification is disabled via InsecureSkipVerify. This allows man-in-the-middle attacks. Remove InsecureSkipVerify or set it to false.

(coderabbit.tls.go-insecure-skip-verify)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@test/e2e/steps/demo_steps.go` around lines 137 - 150, Update
catalogPortForwardAlive to return false when the probe receives a non-2xx HTTP
status, and propagate a false result if resp.Body.Close() returns an error; only
return true after both the request succeeds with a successful status and the
response body closes successfully.

Source: Path instructions

Comment on lines 175 to 177
script := fmt.Sprintf(
`curl -s -k https://%s/catalogs/%s/api/v1/all | jq -s '%s'`,
`set -o pipefail; curl -sS -k --compressed --fail https://%s/catalogs/%s/api/v1/all | jq '%s'`,
addr, catalogName, jqFilter,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bashset -euo pipefail
# Trace Gherkin captures into the shell command and inspect the CI trust boundary.
ast-grep outline test/e2e/steps/demo_steps.go --items all --type function \
--match 'RegisterDemoSteps|catalogCurlJq|PackageHasSomeChannels|PackageHasSomeBundles'
rg -n -C 4 --glob '*.feature' \
'catalog "[^"]*"|package "[^"]*" in catalog'test
rg -n -C 5 --type go \
'\bcatalogCurlJq\s*\(|\bbash\s*\(' test/e2e
fd -t f -e yml -e yaml .github 2>/dev/null \
| xargs -r rg -n -C 3 'pull_request_target|workflow_run|artifact|credentials|kubeconfig'

Repository: openshift/operator-framework-operator-controller

Length of output: 31891


🏁 Script executed:

#!/usr/bin/env bashset -euo pipefail
sed -n '15,35p;166,230p' test/e2e/steps/demo_steps.go
python3 - <<'PY'from pathlib import Pathimport res = Path("test/e2e/steps/demo_steps.go").read_text()patterns = re.findall(r'sc\.Step\(`([^`]+)`', s)for p in patterns: if "package" in p or "catalog" in p: print(p)# Model the two interpolations without executing the resulting command.catalog = 'safe; echo CATALOG_PWNED; #'package = 'safe"; echo PACKAGE_PWNED; #'jq = f'objects | select(.schema == "olm.channel") | select(.package == "{package}") | .name'script = ( "set -o pipefail; curl -sS -k --compressed --fail " f"https://127.0.0.1/catalogs/{catalog}/api/v1/all | jq '{jq}'")Path("/tmp/generated-catalog-query.sh").write_text(script)print("\nGenerated command:")print(script)PY
bash -n /tmp/generated-catalog-query.sh;printf'bash -n status: %s\n'"$?"

Repository: openshift/operator-framework-operator-controller

Length of output: 4317


Injection (CWE-78): Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Reachability: Internal

Remove shell interpolation from catalog queries.

catalogName and packageName come from Gherkin captures and can inject commands into bash -c. Use separate exec.CommandContext calls for curl and jq; path-escape catalogName and pass packageName through jq --arg.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@test/e2e/steps/demo_steps.go` around lines 175 - 177, Replace the
shell-interpolated script in the catalog query step with separate
exec.CommandContext invocations for curl and jq, preserving pipefail-equivalent
error handling. Path-escape catalogName when constructing the curl URL, and pass
packageName to jq via --arg rather than interpolating it into jqFilter; update
the surrounding query logic in the relevant step function accordingly.

Source: Path instructions

@tmshort

Copy link
Copy Markdown
Contributor

/retest

pedjakand others added 4 commits August 5, 2026 17:43
…2848)
Serial tests (HA, TLS, proxy scenarios) patch operator-controller and
catalogd Deployments, triggering rolling updates that delete the
original pods. The support bundle collected at the end only captures
replacement pod logs, so parallel test failure logs are lost.
Deploy Fluent Bit (gated on ARTIFACT_PATH) to continuously persist
olmv1-system container logs to the node filesystem. A copyFromHost
collector in the support bundle extracts these persisted logs into the
operator-logs/ directory, preserving the complete log history across
all pod generations including deleted and restarted instances.
Co-authored-by: Claude <noreply@anthropic.com>
Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.70.0 to 0.70.1.
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.70.0...v0.70.1)
---
updated-dependencies:
- dependency-name: github.com/prometheus/common
dependency-version: 0.70.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [certifi](https://github.com/certifi/python-certifi) from 2026.6.17 to 2026.7.22.
- [Commits](certifi/python-certifi@2026.06.17...2026.07.22)
---
updated-dependencies:
- dependency-name: certifi
dependency-version: 2026.7.22
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.9 to 2.9.1.
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.9...2.9.1)
---
updated-dependencies:
- dependency-name: soupsieve
dependency-version: 2.9.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
tmshortand others added 16 commits August 12, 2026 00:08
It's no longer bring used.
Signed-off-by: Todd Short <tshort@redhat.com>
Adds a new test that verifies cluster-olm-operator correctly configures
operator-controller and catalogd deployments based on the cluster's
control plane topology:
- HA topologies (HighlyAvailable, HighlyAvailableArbiter, DualReplica):
replicas=2 with a PodDisruptionBudget present
- Non-HA topologies (SingleReplica/SNO, External): replicas=1, no PDB
Also registers policyv1 in the test scheme to support PDB list queries.
Assisted-by: claude
Signed-off-by: Todd Short <tshort@redhat.com>
… builders
Signed-off-by: Todd Short <tshort@redhat.com>
Set catalog image tags to v5.0 for the 4.23/5.0 release.
Dynamically discover an installable package from the serving catalogs
instead of hardcoding quay-operator v3.13.10, preferring quay-operator,
cluster-logging, serverless-operator, logic-operator in that order then
alling back to the first available package.
Signed-off-by: Todd Short <tshort@redhat.com>
…ntal manifests
HelmChartSupport was removed upstream in dbc9b4a but the downstream
experimental.yaml values file and its generated manifest still referenced
it, causing operator-controller to crash on startup with:
invalid argument "HelmChartSupport=false" for "--feature-gates" flag:
unrecognized feature gate: HelmChartSupport
This made the OLM cluster operator Degraded/Unavailable and caused cluster
installation to time out (exit code 6).
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…cluster version
Add a second ReleaseGate-eligible OTE test verifying that an operator
whose olm.maxOpenShiftVersion exceeds the current cluster version does
not block cluster upgrade (InstalledOLMOperatorsUpgradeable stays True).
The existing test only covered the blocking path (maxOCPVersion ==
current version → False). This covers the complementary allow path
(maxOCPVersion == next minor → True), directly exercising the
normalization logic introduced for the 4.23/5.0 co-release boundary.
A nextMinorVersion() helper mirrors the 4.23→5.1 special case so the
bundle annotation is always set to the correct next upgrade target.
Run 'make build-update' to register the new allow-case test in the
extension metadata after adding it to olmv1-incompatible.go.
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Todd Short <tshort@redhat.com>
Automate the ClusterExtension rollout failure coverage for OCP-88331 and OCP-88332 by building in-cluster bundle and catalog images for successful and failing bundle versions.
The new QE specs verify ProgressDeadlineExceeded on an initial failed rollout and ProbeFailure while upgrading to a bad revision under the BoxCutter runtime.
Signed-off-by: Daniel Franz <dfranz@redhat.com>
Co-authored-by: Bruno Andrade <bruno.balint@gmail.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Todd Short <tshort@redhat.com>
…eAccount usage in ClusterExtension API, Synthetic Permissions, and PreFlight Admissions
Signed-off-by: Daniel Franz <dfranz@redhat.com>
…grade boundary
Fix GetNextMinorVersion to return "5.1" for 4.23 clusters instead of
"4.24": OCP 4.23 and 5.0 are co-released equivalents whose only upgrade
target is 5.1.
Remove the redundant `&& strings.Contains(message, "5")` guard from the
Upgradeable message poll — the expectedPattern built from
GetNextMinorVersion now encodes the full version string and is
sufficient on its own.
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@openshift-botopenshift-bot added the lgtm Indicates that a PR is ready to be merged. label Aug 12, 2026
@openshift-ciopenshift-ciBot removed the lgtm Indicates that a PR is ready to be merged. label Aug 12, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling required tests:
/test e2e-aws-olmv1-ext
/test e2e-aws-techpreview-olmv1-ext
/test e2e-gcp-ovn-upgrade
/test openshift-e2e-aws-techpreview

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test openshift-e2e-aws

@tmshort

Copy link
Copy Markdown
Contributor

/retest

@tmshort

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ciopenshift-ciBot added the lgtm Indicates that a PR is ready to be merged. label Aug 12, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Tests from second stage were triggered manually. Pipeline can be controlled only manually, until HEAD changes. Use command to trigger second stage.

@openshift-ci

Copy link
Copy Markdown
Contributor

@openshift-bot: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@tmshort

Copy link
Copy Markdown
Contributor

/verified by CI

Most the the changes are dependabot, or apply to the upstream only.

@openshift-ci-robotopenshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Aug 12, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@tmshort: This PR has been marked as verified by CI.

Details

In response to this:

/verified by CI

Most the the changes are dependabot, or apply to the upstream only.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-bot
openshift-merge-botBot merged commit 49582d3 into openshift:mainAug 12, 2026
15 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approvedIndicates a PR has been approved by an approver from all required OWNERS files.jira/valid-referenceIndicates that this PR references a valid Jira ticket of any type.kind/synclgtmIndicates that a PR is ready to be merged.tide/merge-method-mergeDenotes a PR that should use a standard merge by tide when it merges.verifiedSignifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@openshift-bot@openshift-ci-robot@tmshort@pedjak@dtfranz@camilamacedo86@kuiwang02@jianzhangbjz@Xia-Zhao-rh@rashmigottipati@bandrade@oceanc80@ehearne-redhat@sosiouxme@stbenjam@fgiudici@joelanford